Security
Posts tagged with Security.
Category
Tags
24 more tagsFewer tags
Newsletter
New posts land in your inbox when they publish. No spam, unsubscribe anytime.
You're in. New posts head your way.
Filters1
Category
Tags
24 more tagsFewer tags
31 posts

VS Code assisted approvals let the model skip the prompt
Turn on VS Code assisted approvals so Copilot skips low-risk tool prompts on long tasks. Pin Copilot on the agent host, pick Assisted, keep a hard ask.

Write settings.json without granting git star main
Write Claude Code settings that allow git commit and git log without a star before the subcommand. Restart with no 2.1.246 warning, and git push still asks.

Binance let Claude Code trade and the safety model is a subaccount
Binance Agent OS lets Claude Code trade inside a funded sub-account. Blocked withdrawals are not a max-loss. Size the transfer before you click yes now.

JFrog Boost almost granted rm rf on Always Allow
JFrog Boost almost turned Always Allow into rm rf. After boost init, read the first token on the permission card. Bless ls if you want. Never bless the wrapper.

MCP went stateless and the session just moved
Stateless MCP deleted the protocol session. Continuity now rides in requestState on retry. Delete sticky routing, keep the store for carts and tokens.

Agents request every OAuth scope they might need
MCP oauth scopes arrive as a catalog because the next call is unknown. Check the issued token, hide tools you did not get, and keep the agent running.

Bot Preference Sync admits robots.txt never enforced
Bot Preference Sync writes your Search, Agent, and Training policy into robots.txt. A mismatch is an argument to keep crawling. The WAF is still the lock.

MCP is now traffic a firewall can name
MCP traffic detection now matches protocol headers, not mcp in the hostname. Treat the next remote MCP install as a named network event, not a config tweak.

Skill scanning is antivirus for markdown
Skill scanning checks a third-party zip on upload before it can run. Turn the Enterprise toggle on, then still open the folder and read allowed-tools.